Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly recommends saving the API key to a local JSON file as a fallback, but it does not warn that this is plaintext credential storage or require restrictive file permissions. On multi-user systems, shared workspaces, synced home directories, backups, logs, or malware-compromised hosts, this can expose the bearer token and allow unauthorized posting or account impersonation.
